3 ms·
"Unfortunately, a TLS handshake fully exposes the target hostname in plaintext, since the hostname is included in the SNI header in the clear. This remains the
by textmode 8y ago
"Unfortunately, a TLS handshake fully exposes the target hostname in plaintext, since the hostname is included in the SNI header in the clear. This remains the case even in TLS 1.3, and it gives a censor all they need."
Does this mean that endpoints that require SNI are potentially contributing to censorship?
Facts: SNI is optional. Not all websites require it. For example, https://signal.org https://signal.org does not require SNI; clients that do not send SNI can be used to fetch this blog post, without exposing the hostname.
- thefifthsetpin 8y agoSure, but the censor can just censor requests that omit SNI.
- textmode 8y ago"According to our communication with the International Computer Science Institute's certificate notary, which observes on the order of 50 million TLS connections daily, 16.5% of TLS connections in June 2014 lacked SNI, which is enough to make it difficult for a censor to block SNI-less TLS outright." Fifield et al. Proceedings on Privacy Enhancing Technologies 2015(2):1-19 at 2.
- krallja 8y agoThe process listening to IPs that resolve as signal.org must not have alternative hosts on it, since the web server can’t choose a certificate based on anything but IP. Now the censor can just block your IP.
- deleted 8y ago[deleted]
- textmode 8y agos/send/& correct/